Your Website Was Hacked: What to Do in the First Hour

22 Apr 2026 · 5 min read · A Plus Solution

Your Website Was Hacked: What to Do in the First Hour
Quick answer

If your website is hacked, act in order: stay calm, record what you see, tell your host and key team members, change passwords from a clean device, take the site offline or into maintenance mode if customers are at risk, preserve logs and backups, and bring in a security professional. Restore only from a known-clean backup after the cause is closed.

Key takeaways
  • Do not panic-delete everything; preserve evidence and logs first.
  • Change credentials from a clean device, starting with hosting, admin and email.
  • Contain the problem before cleaning: isolate the site and warn customers if needed.
  • Restore from a clean backup only after the entry point is found and fixed.

How do you know your website has been hacked?

Signs vary. You may see defaced pages, strange redirects to unrelated sites, pop-ups, unknown admin users, unexpected emails sent from your domain, a sudden slowdown, or a browser warning that the site is unsafe. Sometimes the first clue is a customer message or a notice from your host or search engine.

Some compromises are invisible to visitors. Hidden pages may be added for spam, or code may skim payment details at checkout. If something feels off, do not dismiss it. Compare against recent changes you made, check with your developer, and treat unexplained behaviour as a possible incident until proven otherwise.

What should you do in the first ten minutes?

Stay calm and write down what you see, with screenshots and the time. Tell the people who need to know: your developer or agency, your hosting provider and a senior person in the business. Avoid rushing to delete files, because the evidence of how the attacker got in may be inside them.

From a device you trust, not the one you suspect is infected, change passwords for hosting, the website admin, FTP or SSH, the database and the email accounts connected to the site. Turn on multi-factor sign-in where available. Then decide whether to put the site into maintenance mode or take it offline, especially if it takes payments or collects personal data.

  • Record screenshots, times and what changed.
  • Alert your host, developer and a decision-maker.
  • Change hosting, admin, database and email passwords from a clean device.
  • Enable maintenance mode or take the site offline if customers are at risk.
  • Do not delete logs or files yet.

How do you contain the damage?

Containment means stopping the attacker from doing more. Ask your host to suspend the account temporarily or block suspicious traffic, remove unknown administrator users, and disable plugins or extensions that were recently added or are out of date. If your site shares a server with other sites, check those too, because attackers often move sideways.

Think about your customers as well. If you handle orders, logins or enquiries, decide whether to pause checkout, reset customer passwords and send a clear, honest notice. Do not hide a real data exposure; the right communication depends on what was affected, and you should take professional and legal advice on obligations.

Why is finding the entry point important?

Cleaning visible damage without understanding the cause means you will probably be hacked again. Common causes include outdated software, weak or reused passwords, vulnerable plugins or themes, compromised hosting accounts and insecure file permissions. The logs from your server and application often show where the first suspicious request came from.

A security professional can examine logs, scan files, compare them with a clean copy and identify backdoors that let the attacker return. This forensic step is also valuable if you need a record for your bank, insurer or authorities. Rushing to restore without it is the most common reason for repeat incidents.

How do you recover safely?

Restore from a backup taken before the compromise, ideally to a freshly secured environment, with all software updated and all credentials changed. Check that the backup itself is clean; some attackers plant code weeks before they act. Then re-enable the site gradually and watch logs closely for several days.

If search engines or browsers flagged your site, request a review once it is clean. Notify any third parties whose credentials or data may have been exposed. If you have no recent backup, a professional clean-up is possible but takes longer and must be done carefully, so budget time for it.

  • Rebuild or restore on a patched, freshly secured environment.
  • Update the CMS, plugins, themes and server software.
  • Remove unused plugins and unknown users.
  • Request a review if a browser or search engine flagged the site.
  • Monitor logs and file changes for at least a week.

Who should you report a website hack to?

Report first to your hosting provider and, if payments are involved, to your payment gateway and bank. If personal data or money may have been compromised, consider reporting to the official cybercrime portal in India and to any regulator that applies to your sector. Check the current official guidance, because reporting duties differ by situation.

Keep a record of what happened, what you did and when. A short internal review afterwards, covering what failed and what will change, turns a bad day into a stronger setup. Regular patching, backups and monitoring are far cheaper than recovery.

Step by step

  1. Stay calm and document. Capture screenshots, times and symptoms before changing anything.
  2. Alert the right people. Inform your developer, host and a business decision-maker straight away.
  3. Secure credentials. From a clean device, change hosting, admin, database and email passwords and enable multi-factor sign-in.
  4. Contain the site. Use maintenance mode or take the site offline, and remove unknown users and risky plugins.
  5. Investigate and clean. Preserve logs, find the entry point and remove backdoors with professional help.
  6. Restore and monitor. Restore from a clean backup on a patched system and watch activity closely afterwards.

Frequently asked questions

Should I delete the infected files myself?

Not before preserving a copy and the logs. Deleting blindly can destroy evidence and miss hidden backdoors, so get a professional to guide the clean-up.

Can I just restore my last backup?

Only if you are sure it predates the compromise and the original weakness is fixed. Otherwise the attacker can walk straight back in.

Will Google remove warnings automatically?

Warnings usually clear after the site is verified clean and a review is requested through the relevant search console. Check the current process in the official help pages.

How can we reduce the chance of another hack?

Keep software updated, remove unused plugins, use strong unique passwords with multi-factor sign-in, take regular off-server backups and have your site tested periodically.

Need help with this? Ask us a question about it — we reply within one working day.

Related services
Keep reading

Get a free automation audit

Tell us one process that eats your team’s time. We reply with what can be automated, roughly how, and what it would save.

Request it →
Start a project

Let’s build
something that
means more.

Talk toYash Parikh
+91 99208 98972
Emailinfo@aplusolution.in
StudioA-1304, Naman Premier, Military Road,
Andheri East, Mumbai 400059
Social